US11588677B2ActiveUtilityA1

System and a method for recognizing and addressing network alarms in a computer network

Assignee: HEWLETT PACKARD ENTPR DEV LPPriority: Mar 2, 2020Filed: Feb 18, 2021Granted: Feb 21, 2023
Est. expiryMar 2, 2040(~13.6 yrs left)· nominal 20-yr term from priority
H04L 41/0631H04L 41/16
47
PatentIndex Score
0
Cited by
19
References
19
Claims

Abstract

The present invention relates a system and a method of recognizing and addressing network alarms in a computer network. A network adapter is configured to receive network alarms related to operating condition of network devices present in the computer network, wherein the network devices are managed by different vendors. Information present in the network alarms is analyzed to determine elements indicating the operating condition of the network devices. The elements may comprise at least one of keywords, object identifiers, and values of the object identifiers. A trained data model is finally used for mapping the network alarms with standard attributes. Based on such mappings, the network alarms are then addressed.

Claims

exact text as granted — not AI-modified
The invention claimed is: 
     
       1. A method comprising:
 receiving, using a network adapter, a network alarm related to an operating condition of a network device present in a computer network; 
 analyzing information present in the network alarm to determine elements indicating the operating condition of the network device, wherein the elements comprise at least one of keywords, object identifiers, and values of the object identifiers; 
 mapping, by a trained data model, the network alarm with one or more standard attributes, 
 wherein the trained data model is developed by learning upon a plurality of network alarms indicating operating conditions of a plurality of network devices and attributes pre-identified to be associated with each of the plurality of network alarms; 
 in response to a first standard attribute not existing, creating, by the trained data model, a new attribute corresponding to the network alarm; 
 replacing at least one of the elements indicating the operating condition of the network device in the network alarm with the first standard attribute; and 
 providing the first standard attribute to a Network Operation Center (NOC). 
 
     
     
       2. The method as claimed in  claim 1 , wherein the plurality of network devices belong to different vendors and have different alarm formats. 
     
     
       3. The method as claimed in  claim 1 , wherein objects of the network alarm is mapped with the standard attributes. 
     
     
       4. The method as claimed in  claim 1 , wherein the standard attributes include Specific Problem, Severity, Priority, Unique Identifier, Probable Cause, Enumeration value, and Clearance. 
     
     
       5. The method as claimed in  claim 1 , wherein the standard attributes are pre-identified to be associated with the plurality of network alarms based on definitions of the elements that are stored in Management Information Bases (MIBs) corresponding to the plurality of network devices. 
     
     
       6. The method as claimed in  claim 1 , wherein the mapping is performed using a supervised and unsupervised learning techniques. 
     
     
       7. The method as claimed in  claim 1 , wherein the network alarm is formatted in accordance with a Simple Network Management Protocol (SNMP) from the plurality of network devices, and wherein the plurality of network devices belong to different vendors. 
     
     
       8. The method as claimed in  claim 1 , further comprising:
 when the at least one of keywords is “Trap,” “Temperature,” “Fail,” or “Assert,” increasing a ranking of the network alarm. 
 
     
     
       9. The method as claimed in  claim 1 , wherein the trained data model uses an unsupervised learning technique. 
     
     
       10. The method as claimed in  claim 1 , further comprising:
 implementing post configuring of the plurality of network alarms based on a corresponding VarBind, wherein the VarBind comprises encrypted alert data included in the network alarm. 
 
     
     
       11. The method as claimed in  claim 1 , further comprising:
 enriching the network alarm using one or more clearance values. 
 
     
     
       12. The method as claimed in  claim 1 , further comprising:
 enriching the network alarm using a host name or source internet protocol (IP) address. 
 
     
     
       13. A system comprising:
 processor; and 
 a memory including instructions that, when executed on the processor, cause the system to:
 receive a network alarm related to an operating condition of a network device present in a computer network; 
 analyze information present in the network alarm to determine elements indicating the operating condition of the network device, wherein the elements comprise at least one of keywords, object identifiers, and values of the object identifiers; 
 map, by a trained data model, the network alarm with one or more standard attributes, 
 wherein the trained data model is developed by learning upon a plurality of network alarms indicating operating conditions of a plurality of network devices and attributes pre-identified to be associated with each of the plurality of network alarms; 
 when a first standard attribute does not exist, create, by the trained data model, a new attribute corresponding to the network alarm; 
 replacing at least one of the elements indicating the operating condition of the network device in the network alarm with the first standard attribute; and 
 providing the first standard attribute to a Network Operation Center (NOC). 
 
 
     
     
       14. The system as claimed in  claim 13 , wherein the plurality of network devices belong to different vendors and have different alarm formats. 
     
     
       15. The system as claimed in  claim 13 , wherein objects of the network alarm is mapped with the standard attributes. 
     
     
       16. The system as claimed in  claim 13 , wherein the standard attributes include Specific Problem, Severity, Priority, Unique Identifier, Probable Cause, Enumeration value, and Clearance. 
     
     
       17. The system as claimed in  claim 13 , wherein the standard attributes are pre-identified to be associated with the plurality of network alarms based on definitions of the elements that are stored in Management Information Bases (MIBs) corresponding to the plurality of network devices. 
     
     
       18. The system as claimed in  claim 13 , wherein the mapping is performed using a supervised and unsupervised learning techniques. 
     
     
       19. A non-transitory, computer readable medium including instructions that, when executed by processing circuitry, cause a system to:
 receive a network alarm related to an operating condition of a network device present in a computer network; 
 analyze information present in the network alarm to determine elements indicating the operating condition of the network device, wherein the elements comprise at least one of keywords, object identifiers, and values of the object identifiers; and 
 map, by a trained data model, the network alarm with one or more standard attributes, 
 wherein the trained data model is developed by learning upon a plurality of network alarms indicating operating conditions of a plurality of network devices and attributes pre-identified to be associated with each of the plurality of network alarms; 
 when a first standard attribute does not exist, create, by the trained data model, a new attribute corresponding to the network alarm; 
 replacing at least one of the elements indicating the operating condition of the network device in the network alarm with the first standard attribute; and 
 providing the first standard attribute to a Network Operation Center (NOC).

Join the waitlist — get patent alerts

Track US11588677B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.